Skip to main content

Integrations

Connect the agents you already run

Vidimus reaches your agent through the interface it already exposes. Paste a request that already works, check that the agent answers, then run the tests. Nothing to install.

Wire protocols
7
Authentication methods
6
Registry connectors
7
Software to install
None

Three steps, then the run

The same flow for every agent, whatever built it.

  1. 01

    Where is the agent

    A reachability check gives a plain verdict, and the fix when something blocks. Protocol detection sends at most 12 requests, and shows you each one.

  2. 02

    How to call it

    Paste a request that already works: a curl command, a HAR file, a Postman request, JavaScript fetch, Python requests or a raw HTTP exchange. Or pick a platform, or fill it in by hand.

  3. 03

    Check that it answers

    One real message goes through the same code a test run uses. The connection is saved as verified, with the name of the person and the time.

The interfaces Vidimus speaks

Seven wire protocols, with ready-made settings for the platforms banks and insurers run.

JSON over HTTP

Typical platforms
n8n, Make, a service your team wrote, an API gateway in front of either

JSON over HTTP, with tool calls in the reply

Typical platforms
In-house agents that return the tools they called with the reply

OpenAI-compatible chat completions

Typical platforms
Azure OpenAI, vLLM, LiteLLM, an Amazon Bedrock gateway, a Databricks gateway

OpenAI Responses API

Typical platforms
OpenAI, Azure AI Foundry

Microsoft Direct Line (Copilot Studio)

Typical platforms
Microsoft Copilot Studio, Power Automate, Azure Bot Service

A2A

Typical platforms
Google ADK, any A2A 1.0, 0.3 or 0.2 server

MCP

Typical platforms
an MCP server behind your gateway, a tool server your platform team runs

Streaming (server-sent events)

Typical platforms
Chat front ends that stream the answer

Event or webhook (back-office agent)

Typical platforms
Back-office agents started by a queue message or a webhook

Interfaces Vidimus connects to today, and the platforms that usually sit behind them.

Multi-turn tests carry the conversation: message history, A2A context and Direct Line conversation.

On request

Agents hosted on these platforms: tell us, and we build the adapter.

  • LangGraph Platform
  • Salesforce Agentforce
  • ServiceNow AI Agents
  • AWS Bedrock AgentCore
  • Vertex AI Agent Engine

Authentication

Six ways to authenticate, from an open test endpoint to mutual TLS.

None
An open endpoint, such as a test environment.
Header
A bearer token or an API key, in the header your gateway expects.
API key in the address
An API key in the query string, as some gateways require.
OAuth 2.0 client credentials
Client credentials, with audience or resource, in basic or body form. The token is fetched and cached for you.
Google service account
A Google service account, exchanged for an access token.
Mutual TLS
A client certificate, for mutual TLS.

Credentials sit in a vault; Vidimus stores only their reference. A secret found in a pasted command is never saved unless you type it again.

What a test run sends

What your agent receives, and what Vidimus keeps.

Tests per run

What to expect
Up to 150, trimmed by severity above that. The trimmed tests are named.

Attempts per test

What to expect
10, so a run makes at most 1,500 attempts. A multi-turn attempt sends one message per turn, up to five, and Direct Line and A2A poll until the reply arrives.

Pace

What to expect
A limited number of requests at once, and a rate limit per agent.

Stopping

What to expect
Any run can be cancelled at any time.

Typical duration

What to expect
28 tests, 280 attempts: 22 minutes in our reference run.

What is recorded

What to expect
Every prompt, reply and tool call, kept in the EU.

Tool calls

What to expect
Read from the reply, the tool log or the event trace. A call to a tool the agent never declared is a finding.

Sub-agents

What to expect
Your orchestrator (LangGraph, AutoGen, CrewAI) can push traces to a webhook for each agent, matched to each test.

The traffic of one test run, and what is recorded.

Your inventory, synced

Vidimus pulls agents from where they are already registered, every six hours or on demand. A person’s registration is never overwritten: a change opens a review item.

  • Google Gemini Enterprise Agent Registry
  • Microsoft Agent 365 (Entra Agent ID)
  • Amazon Bedrock AgentCore
  • A2A well-known discovery
  • MCP registry
  • agentregistry (aregistry.ai, Apicurio)

Or push agents yourself: POST /api/v1/registry/agents, described in OpenAPI, or a CSV or JSON upload. The registry API

Already keep the inventory in a GRC suite? How the two fit together: Vidimus compared with GRC suites and red teaming.

Registration pre-filled from your code

Point Vidimus at a GitLab or Bitbucket repository, or a folder read in your browser. It proposes answers with file and line, including system-prompt wording that bears on Article 50 or Article 5. A person accepts or rejects each one.

Agents that never leave your network

Run Vidimus inside your estate: self-hosted deployment on Enterprise, on request. The tests then reach the agent from inside your network.

Integration questions

Do we need to install anything?

No. Vidimus calls your agent from outside, through the interface it already exposes, the way a user does.

Can you test our production endpoint?

Yes. A run is capped at 150 tests of 10 attempts, throttled per agent, and can be cancelled at any time. Use a test endpoint if you prefer. Credentials sit in a vault; prompts and replies stay in the EU.

Our agent is behind a firewall. Can you reach it?

Run Vidimus inside your estate: self-hosted deployment on Enterprise, on request. The tests then reach the agent from inside your network. There is no fixed address range to allow.

Does Vidimus see our system prompt?

Only what you choose to share. The tests reach the agent from outside, like a user. If you use the code scan, it proposes the prompt wording that bears on Article 50 or Article 5, and you accept or reject each item. The judge never receives your system prompt.

Pilot

Connect one agent, see its evidence

A pilot starts with one request that already works against one of your agents, and ends with a signed evidence pack.

Pilot

  • One agent, end to end
  • Ends with a walkthrough of the evidence pack with your risk and compliance leads
  • Credited against the first year